CYB236 Chapter 8: Host-based Intrusion Detection Systems
25 Questions
0 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

What is the primary function of a host-based IDPS?

  • To monitor the Internet for potential threats
  • To monitor the entire network for suspicious activity
  • To monitor the organization's firewall for unauthorized access
  • To monitor the characteristics of a single host and the events occurring within that host for suspicious activity (correct)
  • What is the typical component of most host-based IDPSs installed on the hosts of interest?

  • Proxies
  • Sensors
  • Agents (correct)
  • Gateways
  • What does an agent designed to monitor a server typically monitor?

  • The OS and common client applications
  • The OS and some common applications (correct)
  • Only the operating system (OS)
  • Only common applications
  • What is an application-based IDPS also known as?

    <p>Some agents perform monitoring for a specific application service only</p> Signup and view all the answers

    Where do agents deploy to in a network architecture?

    <p>To existing hosts on the organization's networks</p> Signup and view all the answers

    What do agents communicate over in a network architecture?

    <p>Same networks</p> Signup and view all the answers

    What is the primary difference between a host-based IDPS and a network-based IDPS?

    <p>The scope of monitoring</p> Signup and view all the answers

    What is the purpose of a prevention action in a host-based IDPS?

    <p>To respond to suspicious activity</p> Signup and view all the answers

    What is the primary function of a shim in a host-based IDPS?

    <p>To intercept, analyse, and determine allowing or denying access</p> Signup and view all the answers

    What type of architecture do host-based IDPSs use?

    <p>Host-based</p> Signup and view all the answers

    What is logged by host-based IDPSs?

    <p>Timestamp, event type, event details, and prevention action performed</p> Signup and view all the answers

    What is an example of an event detected by host-based IDPSs?

    <p>All of the above</p> Signup and view all the answers

    What is a limitation of host-based IDPSs?

    <p>All of the above</p> Signup and view all the answers

    What is a prevention capability of host-based IDPSs?

    <p>Preventing code from being executed</p> Signup and view all the answers

    Where are appliance-based agents deployed?

    <p>Inline, in front of the hosts they protect</p> Signup and view all the answers

    What is a security capability of host-based IDPSs?

    <p>All of the above</p> Signup and view all the answers

    What is the primary purpose of Network Traffic Filtering?

    <p>To prevent unauthorized access and acceptable use policy violations</p> Signup and view all the answers

    What is the function of Filesystem Monitoring?

    <p>To prevent files from being accessed, modified, replaced, or deleted</p> Signup and view all the answers

    What is the purpose of Removable Media Restriction?

    <p>To prevent malware from being transferred or copied to or from the host</p> Signup and view all the answers

    What does Audiovisual Device Monitoring indicate?

    <p>If the host is compromised</p> Signup and view all the answers

    What is the function of Host Hardening?

    <p>To detect and enable disabled security functions</p> Signup and view all the answers

    What is the purpose of Process Status Monitoring?

    <p>To monitor the status of processes or services and security programs</p> Signup and view all the answers

    What is Network Traffic Sanitization used for?

    <p>To prevent sensitive information from being displayed on web server pages</p> Signup and view all the answers

    What is unique about updating agents in host-based IDPSs?

    <p>It is related to the type of operating system</p> Signup and view all the answers

    What is a common capability offered by most host-based IDPSs?

    <p>Management capabilities</p> Signup and view all the answers

    More Like This

    Use Quizgecko on...
    Browser
    Browser